Oval Definition:
oval:org.mitre.oval:def:5408
Revision Date
:
2011-10-31
Version
:
45
Title
:
LSASS Bypass Vulnerability
Description
:
Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2007-5352
Platform(s)
:
Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s)
:
Definition Synopsis
Vulnerable Windows 2000 SP4
Microsoft Windows 2000 SP4 or later is installed
AND
the version of lsasrv.dll is less than 5.0.2195.7147
OR
Vulnerable Windows XP SP2
Microsoft Windows XP SP2 or later is installed
AND
the version of lsasrv.dll is less than 5.1.2600.3249
OR
Vulnerable Windows XP x64 SP1/Server 2003 SP1 x86/x64/ia-64
Windows XP x64 SP1/Server 2003 SP1 x86/x64/ia-64
Microsoft Windows XP Professional x64 Edition SP1 is installed
OR
Microsoft Windows Server 2003 SP1 (x86) is installed
OR
Microsoft Windows Server 2003 SP1 (x64) is installed
OR
Microsoft Windows Server 2003 SP1 for Itanium is installed
AND
the version of lsasrv.dll is less than 5.2.3790.3041
OR
Vulnerable Windows XP x64 SP2/Server 2003 SP2 x86/x64/ia-64
Windows XP x64 SP2/Server 2003 SP2 x86/x64/ia-64
Microsoft Windows XP x64 Edition SP2 is installed
OR
Microsoft Windows Server 2003 SP2 (x86) is installed
OR
Microsoft Windows Server 2003 SP2 (x64) is installed
OR
Microsoft Windows Server 2003 (ia64) SP2 is installed
AND
the version of lsasrv.dll is less than 5.2.3790.4186
BACK